> ## Documentation Index
> Fetch the complete documentation index at: https://docs.postinger.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CLI authentication

> Browser sessions, API keys, and choosing a server.

## Browser sessions

```bash theme={null}
postinger auth login --name "Work laptop"
postinger auth status
postinger doctor
```

Authorization requests expire after ten minutes. Browser login grants account and analytics reads, media access, and post reading, editing, and publishing. **Post deletion is excluded.** Use a separately scoped API key for deletion.

Device sessions last at most 90 days. Their access tokens last at most one hour and renew automatically. Manage devices under **Project settings → Connected apps**.

```bash theme={null}
postinger auth logout
```

For a browser session, logout revokes the device before removing local credentials. `auth logout --local` removes only the local file. For a manually supplied API key, logout removes the local copy without revoking the key; revoke it in the dashboard when needed.

## API keys and automation

Create a customer key in **API keys**, with permissions appropriate for the job. Provide it through your environment or pipe it into login:

```bash theme={null}
export POSTINGER_API_URL=https://api.dev.postinger.dev
# Set POSTINGER_API_KEY using your shell or secret manager.
printf '%s' "$POSTINGER_API_KEY" | postinger auth login --key-stdin
postinger auth status
```

Setting `POSTINGER_API_KEY` is also enough to run commands without a saved login. It overrides saved credentials. Pair it with `POSTINGER_API_URL` when using another environment.

## Choose a server

```bash theme={null}
postinger --api-url https://api.dev.postinger.dev auth login
```

An explicit `--api-url` takes priority over the environment and saved URL. Without explicit configuration, the CLI uses the saved login's URL or `https://api.dev.postinger.dev`. A saved credential cannot silently move to another server.

Credentials live in `$XDG_CONFIG_HOME/postinger/config.json`, or `~/.config/postinger/config.json`. This is a plaintext file with owner-only permissions. Do not commit it or copy it into an MCP tool argument.


## Related topics

- [Authentication and permissions](/guides/authentication.md)
- [CLI quickstart](/cli/quickstart.md)
- [Automate with the CLI](/cli/automation.md)
- [Retries, limits, and errors](/guides/retries-and-errors.md)
- [Verify API credentials and inspect project, expiry and effective permissions](/api-reference/authentication/verify-api-credentials-and-inspect-project-expiry-and-effective-permissions.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.